Mozilla Firefox vulnerabilities
3,233 known vulnerabilities affecting mozilla/firefox.
Total CVEs
3,233
CISA KEV
15
actively exploited
Public exploits
126
Exploited in wild
34
Severity breakdown
CRITICAL914HIGH970MEDIUM1277LOW69UNKNOWN3
Vulnerabilities
Page 101 of 162
CVE-2021-23982P4MEDIUMCVSS 6.5fixed in 87.0≥ unspecified, < 872021-03-31
CVE-2021-23982 [MEDIUM] CWE-326 CVE-2021-23982: Using techniques that built on the slipstream research, a malicious webpage could have scanned both
Using techniques that built on the slipstream research, a malicious webpage could have scanned both an internal network's hosts as well as services running on the user's local machine utilizing WebRTC connections. This vulnerability affects Firefox ESR < 78.9, Firefox < 87, and Thunderbird < 78.9.
nvd
CVE-2024-0753P4MEDIUMCVSS 6.5fixed in 122.0≥ unspecified, < 1222024-01-23
CVE-2024-0753 [MEDIUM] CVE-2024-0753: In specific HSTS configurations an attacker could have bypassed HSTS on a subdomain. This vulnerabil
In specific HSTS configurations an attacker could have bypassed HSTS on a subdomain. This vulnerability affects Firefox < 122, Firefox ESR < 115.7, and Thunderbird < 115.7.
nvd
CVE-2022-45408P4MEDIUMCVSS 6.5fixed in 107.0≥ unspecified, < 1072022-12-22
CVE-2022-45408 [MEDIUM] CWE-79 CVE-2022-45408: Through a series of popups that reuse windowName, an attacker can cause a window to go fullscreen wi
Through a series of popups that reuse windowName, an attacker can cause a window to go fullscreen without the user seeing the notification prompt, resulting in potential user confusion or spoofing attacks. This vulnerability affects Firefox ESR < 102.5, Thunderbird < 102.5, and Firefox < 107.
nvd
CVE-2024-1547P4MEDIUMCVSS 6.5fixed in 115.8.0fixed in 123.0+1 more2024-02-20
CVE-2024-1547 [MEDIUM] CWE-290 CVE-2024-1547: Through a series of API calls and redirects, an attacker-controlled alert dialog could have been dis
Through a series of API calls and redirects, an attacker-controlled alert dialog could have been displayed on another website (with the victim website's URL shown). This vulnerability affects Firefox < 123, Firefox ESR < 115.8, and Thunderbird < 115.8.
nvdosv
CVE-2023-4574P4MEDIUMCVSS 6.5fixed in 117.0≥ 115.0, < 115.2+1 more2023-09-11
CVE-2023-4574 [MEDIUM] CWE-416 CVE-2023-4574: When creating a callback over IPC for showing the Color Picker window, multiple of the same callback
When creating a callback over IPC for showing the Color Picker window, multiple of the same callbacks could have been created at a time and eventually all simultaneously destroyed as soon as one of the callbacks finished. This could have led to a use-after-free causing a potentially exploitable crash. This vulnerability affects Firefox < 117, Firefox
nvd
CVE-2023-4575P4MEDIUMCVSS 6.5fixed in 117.0≥ 115.0, < 115.2+1 more2023-09-11
CVE-2023-4575 [MEDIUM] CWE-416 CVE-2023-4575: When creating a callback over IPC for showing the File Picker window, multiple of the same callbacks
When creating a callback over IPC for showing the File Picker window, multiple of the same callbacks could have been created at a time and eventually all simultaneously destroyed as soon as one of the callbacks finished. This could have led to a use-after-free causing a potentially exploitable crash. This vulnerability affects Firefox < 117, Firefox E
nvd
CVE-2023-23598P4MEDIUMCVSS 6.5fixed in 109.0≥ unspecified, < 1092023-06-02
CVE-2023-23598 [MEDIUM] CVE-2023-23598: Due to the Firefox GTK wrapper code's use of text/plain for drag data and GTK treating all text/plai
Due to the Firefox GTK wrapper code's use of text/plain for drag data and GTK treating all text/plain MIMEs containing file URLs as being dragged a website could arbitrarily read a file via a call to `DataTransfer.setData`. This vulnerability affects Firefox < 109, Firefox ESR < 102.7, and Thunderbird < 102.7.
nvd
CVE-2022-45405P4MEDIUMCVSS 6.5fixed in 107.0≥ unspecified, < 1072022-12-22
CVE-2022-45405 [MEDIUM] CWE-416 CVE-2022-45405: Freeing arbitrary <code>nsIInputStream</code>'s on a different thread than creation could have led t
Freeing arbitrary nsIInputStream's on a different thread than creation could have led to a use-after-free and potentially exploitable crash. This vulnerability affects Firefox ESR < 102.5, Thunderbird < 102.5, and Firefox < 107.
nvd
CVE-2022-46875P4MEDIUMCVSS 6.5fixed in 108.0≥ unspecified, < 1082022-12-22
CVE-2022-46875 [MEDIUM] CWE-287 CVE-2022-46875: The executable file warning was not presented when downloading .atloc and .ftploc files, which can r
The executable file warning was not presented when downloading .atloc and .ftploc files, which can run commands on a user's computer. *Note: This issue only affected Mac OS operating systems. Other operating systems are unaffected.*. This vulnerability affects Firefox < 108, Firefox ESR < 102.6, and Thunderbird < 102.6.
nvd
CVE-2023-25752P4MEDIUMCVSS 6.5fixed in 111.0≥ unspecified, < 1112023-06-02
CVE-2023-25752 [MEDIUM] CVE-2023-25752: When accessing throttled streams, the count of available bytes needed to be checked in the calling f
When accessing throttled streams, the count of available bytes needed to be checked in the calling function to be within bounds. This may have lead future code to be incorrect and vulnerable. This vulnerability affects Firefox < 111, Firefox ESR < 102.9, and Thunderbird < 102.9.
nvd
CVE-2005-0752P4HIGHCVSS 7.5v0.8v0.9+8 more2005-04-18
CVE-2005-0752 [HIGH] CVE-2005-0752: The Plugin Finder Service (PFS) in Firefox before 1.0.3 allows remote attackers to execute arbitrary
The Plugin Finder Service (PFS) in Firefox before 1.0.3 allows remote attackers to execute arbitrary code via a javascript: URL in the PLUGINSPAGE attribute of an EMBED tag.
nvd
CVE-2022-31744P4MEDIUMCVSS 6.5fixed in 101.0≥ unspecified, < 1012022-12-22
CVE-2022-31744 [MEDIUM] CWE-79 CVE-2022-31744: An attacker could have injected CSS into stylesheets accessible via internal URIs, such as resource:
An attacker could have injected CSS into stylesheets accessible via internal URIs, such as resource:, and in doing so bypass a page's Content Security Policy. This vulnerability affects Firefox ESR < 91.11, Thunderbird < 102, Thunderbird < 91.11, and Firefox < 101.
nvd
CVE-2023-3482P4MEDIUMCVSS 6.5fixed in 115.0≥ unspecified, < 1152023-07-05
CVE-2023-3482 [MEDIUM] CWE-862 CVE-2023-3482: When Firefox is configured to block storage of all cookies, it was still possible to store data in l
When Firefox is configured to block storage of all cookies, it was still possible to store data in localstorage by using an iframe with a source of 'about:blank'. This could have led to malicious websites storing tracking data without permission. This vulnerability affects Firefox < 115.
nvdosv
CVE-2022-22750P4MEDIUMCVSS 6.5fixed in 96.0≥ unspecified, < 962022-12-22
CVE-2022-22750 [MEDIUM] CVE-2022-22750: By generally accepting and passing resource handles across processes, a compromised content process
By generally accepting and passing resource handles across processes, a compromised content process might have confused higher privileged processes to interact with handles that the unprivileged process should not have access to.*This bug only affects Firefox for Windows and MacOS. Other operating systems are unaffected.*. This vulnerability affects Firefox
nvd
CVE-2022-45420P4MEDIUMCVSS 6.5fixed in 107.0≥ unspecified, < 1072022-12-22
CVE-2022-45420 [MEDIUM] CWE-1021 CVE-2022-45420: Use tables inside of an iframe, an attacker could have caused iframe contents to be rendered outside
Use tables inside of an iframe, an attacker could have caused iframe contents to be rendered outside the boundaries of the iframe, resulting in potential user confusion or spoofing attacks. This vulnerability affects Firefox ESR < 102.5, Thunderbird < 102.5, and Firefox < 107.
nvd
CVE-2024-10462P4MEDIUMCVSS 6.5fixed in 128.4.0fixed in 132.0+1 more2024-10-29
CVE-2024-10462 [MEDIUM] CWE-290 CVE-2024-10462: Truncation of a long URL could have allowed origin spoofing in a permission prompt. This vulnerabili
Truncation of a long URL could have allowed origin spoofing in a permission prompt. This vulnerability affects Firefox < 132, Firefox ESR < 128.4, Thunderbird < 128.4, and Thunderbird < 132.
nvd
CVE-2024-10465P4MEDIUMCVSS 6.5fixed in 128.4.0fixed in 132.0+1 more2024-10-29
CVE-2024-10465 [MEDIUM] CWE-290 CVE-2024-10465: A clipboard "paste" button could persist across tabs which allowed a spoofing attack. This vulnerabi
A clipboard "paste" button could persist across tabs which allowed a spoofing attack. This vulnerability affects Firefox < 132, Firefox ESR < 128.4, Thunderbird < 128.4, and Thunderbird < 132.
nvd
CVE-2024-7529P4MEDIUMCVSS 6.5fixed in 129.0≥ unspecified, < 1292024-08-06
CVE-2024-7529 [MEDIUM] CWE-451 CVE-2024-7529: The date picker could partially obscure security prompts. This could be used by a malicious site to
The date picker could partially obscure security prompts. This could be used by a malicious site to trick a user into granting permissions. This vulnerability affects Firefox < 129, Firefox ESR < 115.14, Firefox ESR < 128.1, Thunderbird < 128.1, and Thunderbird < 115.14.
nvd
CVE-2023-23600P4MEDIUMCVSS 6.5fixed in 109.0≥ unspecified, < 1092023-06-02
CVE-2023-23600 [MEDIUM] CVE-2023-23600: Per origin notification permissions were being stored in a way that didn't take into account what br
Per origin notification permissions were being stored in a way that didn't take into account what browsing context the permission was granted in. This lead to the possibility of notifications to be displayed during different browsing sessions.
*This bug only affects Firefox for Android. Other operating systems are unaffected.* This vulnerability affects Fir
nvd
CVE-2023-6211P4MEDIUMCVSS 6.5fixed in 120.0≥ unspecified, < 1202023-11-21
CVE-2023-6211 [MEDIUM] CWE-1021 CVE-2023-6211: If an attacker needed a user to load an insecure http: page and knew that user had enabled HTTPS-onl
If an attacker needed a user to load an insecure http: page and knew that user had enabled HTTPS-only mode, the attacker could have tricked the user into clicking to grant an HTTPS-only exception if they could get the user to participate in a clicking game. This vulnerability affects Firefox < 120.
nvdosv